BLOG
KPIs, KRIs and What Boards Actually Want to Know
Published 13 August 2026 ยท By P Larner
Risk Management#KPIs#KRIs#metrics#risk appetite#board reporting
KPIs, KRIs and What Boards Actually Want to Know
Illustration for: KPIs, KRIs and What Boards Actually Want to Know
Most security metrics packs are 60 slides of counts that answer no question a director actually has. The fix is not more data, it is fewer numbers with clearer meaning. This article covers the difference between performance and risk indicators, how to choose a small set, and how to present them so a board can act.
KPIs and KRIs are different questions
The two get used interchangeably, and they should not be. A key performance indicator measures whether your programme is doing what you designed it to do. A key risk indicator measures whether your exposure is moving, regardless of how well the programme is running.
Patch SLA attainment is a KPI, because โ92 per cent of critical patches deployed within 14 daysโ tells you the patching process works. Percentage of estate running end-of-life software is a KRI, because it tells you how much unpatchable exposure you are carrying, and no amount of process excellence moves it, only investment and lifecycle decisions do.
The distinction matters because they fail independently. You can hit every KPI while risk rises, since a team can achieve 100 per cent patch SLA on supported systems while the EOL estate grows from 5 to 15 per cent. Boards that only see KPIs get a comfortable and wrong picture. Boards that only see KRIs get anxiety with no sense of whether the function is competent. Show both, and label which is which.
Here are some paired examples.
KPI, is the programme working? | KRI, is exposure moving? |
|---|---|
Critical patches deployed within SLA | Percentage of assets past end-of-life |
Phishing simulation report rate | Credential pairs found in breach dumps |
Mean time to triage alerts | Externally exposed services with critical vulnerabilities |
Third-party assessments completed on schedule | Percentage of critical suppliers with no assessed posture |
Joiner and leaver access actioned within 24 hours | Dormant privileged accounts |
Leading versus lagging
Cut the same metrics a second way. Lagging indicators describe what already happened, such as incidents last quarter, audit findings and losses. Leading indicators describe conditions that make future incidents more or less likely, such as multi-factor authentication coverage, backup restore test success and mean time to remediate internet-facing criticals.
Boards get lagging indicators by default because they are easy to count, but lagging indicators arrive too late to prevent anything. A board that saw โMFA coverage on remote access stuck at 71 per cent for three quartersโ had the chance to fund the fix before the credential-stuffing incident, not after it. A defensible pack has a majority of leading indicators, with lagging ones kept for context and for testing whether the leading ones actually predicted anything.
Pick 8 to 10, not 60
Every mature metric programme I have seen went through the same arc, an initial explosion to 40 or 60 metrics because everything seemed worth tracking, then a painful cull. Skip the first phase. A board pack should carry 8 to 10 metrics, and each must pass three tests.
Someone owns it
A named person can explain this monthโs value and what they are doing about it.
It can trigger a decision
If the number crossed its threshold, the board would do something specific, whether fund, escalate or accept. If you cannot say what, drop the metric.
It is honest under pressure
If the metric can be gamed, and closing tickets to flatter mean time to resolve is the classic, either fix the measurement or pair it with a countermeasure metric such as reopen rate.
Everything else lives in an operational pack for the CISOโs own team. Nothing is lost, because the board simply is not the audience for endpoint agent version distribution.
Be ready to rotate. When MFA coverage reaches 99 per cent and stays there, retire it to an annual confirmation and promote whatever is now the weakest area. A static pack is a sign nobody is thinking.
Trends and thresholds, not counts
โWe blocked 1.2 million attacks this monthโ is the most common security slide in existence and it carries no information. Nobody knows if 1.2 million is good, and blocked attacks are evidence of the internet being the internet.
Before and after board slides comparing a lone count of blocked attacks with a trended EOL metric against a tolerance threshold
A count versus a decision, where the after slide shows trend, threshold and commentary a board can act on.
Three presentation rules fix most packs.
- Show at least 12 months of trend. A single number invites the question โcompared to what?โ. A line answers it. Direction and rate of change are the story, and the current value is a caption.
- Draw the threshold on the chart. Every metric needs an agreed line, whether target, tolerance or trigger. โEOL assets at 9 per cent against a tolerance of 5 per cent, breached since Marchโ is a sentence a board can act on. Without the threshold, directors are being asked to intuit whether 9 per cent is fine, and they will guess.
- Prefer rates and coverage to volumes. Percentages of estate, of suppliers, of staff. Volumes grow with the business and tell you nothing about control.
And say what changed. Two sentences of commentary per metric, such as โup 3 points following the acquisition, remediation plan agreed, back inside tolerance by Q3โ, is worth more than any amount of chart polish.
Tie the metrics to appetite statements
This is the step most programmes skip, and it is where the board conversation gets easy. If the organisation has a risk appetite statement, every KRI threshold should be derived from it, so the pack becomes a direct report on whether the organisation is living within the appetite it declared.
The chain looks like this. The appetite says โwe have low appetite for technology risk arising from unsupported systemsโ. The tolerance says โno more than 5 per cent of production assets past vendor end-of-life, and none holding personal dataโ. The KRI is EOL percentage, reported monthly against that line. When the metric breaches, the conversation is not โis 9 per cent bad?โ, it is โwe are outside stated appetite, here are the options and costs to get back inside, or here is the case for formally revising the appetiteโ. Both are legitimate outcomes, and both are board decisions rather than security department pleading.
Vertical chain linking an appetite statement to a tolerance, a KRI and the board decision on breach
From appetite statement to board action, where every KRI threshold traces back to declared appetite.
If your organisation has no appetite statements, the metrics work exposes that gap quickly, and drafting tolerance lines for your 8 to 10 chosen metrics is a practical way to force the discussion. In my experience boards find it far easier to debate โis 5 per cent the right line?โ than to draft appetite prose from a blank page.
A pack worth copying
Here is the format that has worked best for me. One summary page with all metrics as red, amber or green against their thresholds, then one page per metric showing the 12-month trend, the threshold line, the owner, and two sentences of commentary. Ten pages, fifteen minutes of a boardโs time, and every number connects to a decision someone could take. Build that, run it for two quarters, and cull anything nobody asked a question about.
Mock board dashboard of nine metric tiles with sparklines and RAG status dots, linked to a single-metric detail page
The one-page summary, with nine labelled KPI and KRI tiles, each backed by a one-page detail view.
Governance command centre dashboard in RaptorGRC
The command centre dashboard in RaptorGRC.
Run your GRC programme in your own network.
RaptorGRC Community Edition is free โ every module, offline licence activation, nothing phones home.
Register / Download Contact us